NexShield is a malicious browser extension for Chrome, and in some reporting Chrome and Edge, that impersonates the legitimate uBlock Origin Lite ad blocker. It was distributed via malvertising that led users to an official Chrome Web Store listing, including the extension ID cpcdkmjddocikjdkbbeiaafnpdbdafmi, and was associated with the developer email alaynna6899@gmail.com. Huntress attributed the campaign using NexShield to the financially motivated threat actor KongTuke.
The extension is described as a near-perfect clone of uBlock Origin Lite, with forged code headers falsely attributing code to Raymond Hill and references to a non-existent GitHub repository or help site to appear legitimate. NexShield generates a UUID and sends install, update, and uninstall telemetry beacons to attacker-controlled infrastructure, including the typosquatted domain nexsnield[.]com. It delays malicious activity using Chrome Alarms, with an initial delay of about 60 minutes and recurring execution every 10 minutes.
Its core malicious behavior is to intentionally exhaust browser resources by creating massive numbers of chrome.runtime port connections in a tight loop, causing severe slowdown, unresponsiveness, and browser crashes. This staged crash behavior is used to support a ClickFix-style social-engineering lure referred to as CrashFix. After the forced restart, victims are shown a fake warning that the browser stopped abnormally and are instructed to open the Windows Run dialog and execute a command. NexShield silently places a malicious PowerShell command on the clipboard for the victim to paste and run. The lure also includes anti-analysis features such as blocking DevTools shortcuts, disabling right-click, and preventing text selection or dragging.
The follow-on infection chain abuses the legitimate Windows LOLBin finger.exe, copying it from System32 to %TEMP% and renaming it to ct.exe. That stage connects to 199.217.98[.]108 and pipes server responses directly to cmd for execution. Subsequent PowerShell stages perform anti-analysis and victim profiling, including checks for more than 50 analysis or security tools, VM artifacts, and whether the host is domain-joined. The chain sends host information, including AV product data and markers indicating WORKGROUP or domain-joined status, to 199.217.98[.]108/n, and executes C2 responses via Invoke-Expression.
For domain-joined hosts, the campaign delivers a portable WinPython environment and a Python RAT named ModeloRAT, including delivery from a Dropbox-hosted archive. ModeloRAT uses RC4-encrypted command-and-control, persists via HKCU\Software\Microsoft\Windows\CurrentVersion\Run using the value name MonitoringService, and beacons over HTTP port 80 to 170.168.103[.]208 and 158.247.252[.]178. Reporting describes this operation as prioritizing enterprise or business targets and notes that a single install of NexShield from an official marketplace can escalate into full remote access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NexShield : A malicious Chrome extension impersonating uBlock Origin Lite, distributed via malvertising and used to stage the CrashFix lure.
"...a malicious browser extension called NexShield that impersonates the legitimate uBlock Origin Lite ad blocker..."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“To evade detection… uses Chrome's Alarms API to delay execution by 60 minutes… then fires every 10 minutes after the initial trigger.”
ClickFix... fake error or fake CAPTCHA tests to trick users into pasting malicious scripts into the Windows Run dialog... FileFix... manually pasting and executing malicious commands... CrashFix... trick them into manually executing code... In each case the victim is ultimately tricked into running an attacker-supplied PowerShell command.
“multiple layers of Base64 encoding and XOR… C2 IP addresses built character-by-character… junk code padding… TWO layers of string encryption… AES-256-CBC… then XOR”
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious Chrome extension masquerading as uBlock Origin Lite and used in Woodgnat attack chains to facilitate the CrashFix social-engineering lure.
A malicious Chrome extension masquerading as uBlock Origin Lite and used in Woodgnat attack chains to stage the CrashFix social-engineering lure.
Fake ad-blocking Chrome/Edge extension used in a malvertising campaign; intentionally crashes the browser and presents a fraudulent 'fix' flow to lead victims into executing malicious commands, ultimately delivering additional payloads (e.g., ModeloRAT).
A malicious Chrome browser extension used to establish an enterprise foothold and escalate into remote access/backdoor capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.